CVE-2026-5270
Last modified
CVE-2026-5270 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue is caused by improper handling of HTTP request paths and headers, which allows an unauthenticated attacker to manipulate requests in a manner that bypasses authentication and associated audit logging controls.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue is caused by improper handling of HTTP request paths and headers, which allows an unauthenticated attacker to manipulate requests in a manner that bypasses authentication and associated audit logging controls.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| CIENA | Navigator NCS | 8.1 |
| CIENA | MCP | <= 8.0 |
| CIENA | Planner Plus OnPrem | <= 4.1 |
| Blue Planet | Inventory | <=24.04.001; <=23.12.401; <=23.08.302; <=23.04.701 |
| Blue Planet | Orchestration | <=24.04.2; <=23.12.3; <=23.08.4; <=23.04.2 |
| Blue Planet | Route Optimization & Analysis | <=24.04.1.2-R; <=23.12.1.6-R; <=23.08.1.6-R; <=23.04.P01-9-R |
| Blue Planet | Unified Assurance & Analytics | <=24.04 MR1; <=23.12 MR3; <=23.04. MR4 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-5270?
How severe is CVE-2026-5270?
How do I fix CVE-2026-5270?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-52694Unauthenticated Sensitive Data Exposure in Signature Add-On …7.5
- CVE-2026-52695Unauthenticated Sensitive Data Exposure in ABC Crypto Checko…7.5
- CVE-2026-52696Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 …7.5
- CVE-2026-52697Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.8.5
- CVE-2026-52698Subscriber Sensitive Data Exposure in PushEngage – Web Push …7.4
- CVE-2026-52699Unauthenticated Insecure Direct Object References (IDOR) in …7.5
- CVE-2026-52700Subscriber SQL Injection in WCMultiShipping <= 3.0.2 version…8.5
- CVE-2026-52701Unauthenticated Broken Access Control in User Registration <…6.5
- CVE-2026-52702Unauthenticated Cross Site Scripting (XSS) in SEO Redirectio…7.1
- CVE-2026-52703Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.9.6
- CVE-2026-52704Improper Control of Generation of Code ('Code Injection') vu…10
- CVE-2026-52705Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI…9
Are you affected by CVE-2026-5270?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
